What personal data betzillo.co.nz collects, why we collect it, how long we keep it, who processes it, and the rights you hold over it under Australian and EU law.
betzillo.co.nz is an independent online casino review platform operated from Sydney, Australia. We are not a casino. We run no gambling services, take no deposits, process no withdrawals and hold no player accounts. Our data processing is correspondingly narrow: we are an informational publisher, and our privacy obligations reflect that.
The casino we review, Betzillo casino, is a separate legal entity run by a third party under a Curaçao licence. Its privacy practices are governed by its own policy, on its own site, and lie entirely outside our control.
When you email us, we receive the following:
When you visit any page on this site, our hosting infrastructure and analytics tools automatically record:
We do not collect your real name, home address, phone number, financial details or government identifiers through any automatic mechanism, and we never knowingly collect data from anyone under 18.
| Purpose | Data used | Legal basis (where GDPR applies) |
|---|---|---|
| Responding to your enquiry | Contact form data, email | Legitimate interest / consent |
| Site analytics (aggregate traffic trends) | Anonymised IP, pages viewed, device type | Legitimate interest |
| Affiliate attribution (tracking referrals) | Click identifier passed to operator | Legitimate interest |
| Security and abuse prevention | IP address, user-agent, request patterns | Legitimate interest |
| Compliance with legal obligations | Server logs | Legal obligation |
We do not use your data to build advertising profiles, run no remarketing, and never sell, rent or trade personal data to third parties for marketing purposes. How we produce review figures is documented in how we test and how we rate casinos, and our commercial model in the affiliate disclosure.
We rely on a small number of processors to run the site. Each operates under its own privacy policy, which governs the specific processing it carries out:
Where these processors move data across borders, we rely on their standard contractual clauses and the adequacy mechanisms they publish. Each third party lists its complete set of sub-processors in its own documentation.
| Category | Retention period |
|---|---|
| Contact-form submissions and email correspondence | 12 months after last interaction, unless longer is needed to resolve an ongoing matter |
| Server access logs (full IP) | 90 days |
| Aggregated analytics (GA4, no PII) | Up to 26 months per GA4 default retention |
| Affiliate click events | Per the affiliate network's policy, typically up to 24 months |
| Editorial records required by correction policy | Retained as long as the corresponding article is live, for audit of the correction log |
Once a retention period ends, the data is deleted or anonymised, and backups rotate on a shorter cycle and expire by themselves.
As an Australian resident, you have the right to do the following:
If you reside in the EU or the UK, you additionally hold rights to data portability, restriction of processing, objection to processing and erasure (the right to be forgotten), subject to the usual legal exceptions.
Email info with "Privacy" in the subject line. We respond within 30 days and verify your identity before disclosing any personal data. The process is documented on the contact page.
Exercising your rights costs nothing. If a request is clearly unfounded or excessive, for example repeated requests for the same data, we may charge a reasonable fee or decline to act, as the law permits.
We use cookies and similar technologies for analytics, security and basic site function. A full list, covering each cookie's purpose, its retention and how to manage it, is on our cookie policy page. You can block or clear non-essential cookies at any time from your browser settings.
Our main processors, Cloudflare and Google Analytics, run global infrastructure, so personal data may be moved to or accessed from jurisdictions outside Australia, usually the United States and Europe. Those transfers operate under the processors' standard contractual clauses and adequacy mechanisms, as set out in their own privacy policies.
Where you have the legal right to object to an international transfer, you can exercise it by emailing the privacy address above. In practice, objecting usually means asking us to delete the data rather than restrict where it sits.
The site runs over TLS 1.2 or higher with modern cipher suites, and the admin side of the hosting uses two-factor authentication. Contact-form submissions and email correspondence live in a mailbox protected by provider-side encryption and 2FA. Within our small team, access to personal data is limited to whoever needs it for the task in hand.
No online system is perfectly secure. If a breach affects your personal information, we will notify those affected and the OAIC under the Notifiable Data Breaches scheme in Australian law, along with any equivalent GDPR obligations where they apply.
This site, the review and every casino discussed on it are for adults aged 18 or over. We do not knowingly collect personal information from anyone under 18. If you are a parent or guardian and believe your child has submitted information to this site, email info and we will delete the submission. Our wider position on minors and gambling is on the responsible gambling page.
We revise this policy when our practices change, whether adding or dropping a processor, adjusting retention periods, or responding to a shift in legal obligations. Any material change moves the "last updated" date at the top, and for significant changes we post a short notice at the top of the homepage and the policy page for at least 30 days.
This document is the current and authoritative version of our privacy practices. Earlier versions are available on request through the contact page. Use of the site is covered by our terms; more about this site and reviewer Mason Caldwell is available, with every page on the sitemap.